Export Endpoints to Seed YAML
Generates one YAML seed snippet covering the listed endpoints. The response is the YAML itself, not JSON: the module name is repeated in the X-Module-Name header and in the Content-Disposition filename, which the Configurator uses when saving the download. Partial failure is not an error. An entry that names no active endpoint — or whose role lookup fails — is dropped and the export succeeds with 200 covering the rest; the only signal is a `# Note: N endpoints could not be exported` comment line in the YAML, and which ones failed appears in the server log only. The request fails with 404 only when NONE of the listed endpoints resolves.
Authorization
BearerAuth In: header
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
text/yaml
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/v1/rbac/endpoint-role/export" \ -H "Content-Type: application/json" \ -d '{ "endpoints": [ { "endpoint": "/v1/customers", "method": "GET" }, { "endpoint": "/v1/customers/%", "method": "PUT" }, { "endpoint": "/v1/customers/{id}", "method": "DELETE" } ] }'"# RBAC seed file for customers module\n# Generated: 2026-08-28 10:15:00\n# Total endpoints: 2\n# Note: 1 endpoints could not be exported\n\nmodule: customers\nendpoints:\n - endpoint: /v1/customers\n method: GET\n roles:\n - User\n - StandardUser\n description: \"GET /v1/customers\"\n\n - endpoint: /v1/customers/%\n method: PUT\n roles:\n - User\n description: \"PUT /v1/customers/%\"\n\n"{
"status": 400,
"code": "rbac_m.endpoint_not_found",
"message": "Invalid input",
"details": [
{
"field": "roles",
"rule": "required",
"param": "string",
"message": "roles is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 400,
"code": "rbac_m.endpoint_not_found",
"message": "Invalid input",
"details": [
{
"field": "roles",
"rule": "required",
"param": "string",
"message": "roles is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 400,
"code": "rbac_m.endpoint_not_found",
"message": "Invalid input",
"details": [
{
"field": "roles",
"rule": "required",
"param": "string",
"message": "roles is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 400,
"code": "rbac_m.endpoint_not_found",
"message": "Invalid input",
"details": [
{
"field": "roles",
"rule": "required",
"param": "string",
"message": "roles is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 400,
"code": "rbac_m.endpoint_not_found",
"message": "Invalid input",
"details": [
{
"field": "roles",
"rule": "required",
"param": "string",
"message": "roles is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 400,
"code": "rbac_m.endpoint_not_found",
"message": "Invalid input",
"details": [
{
"field": "roles",
"rule": "required",
"param": "string",
"message": "roles is required"
}
],
"class": "validation",
"retryable": false
}{
"overall_status": "unhealthy",
"message": "Service is shutting down",
"timestamp": "2019-08-24T14:15:22Z"
}Exports every module's endpoint permissions and writes each one to $DATA_DIR/rbac/<module>.rbac.yaml on the server. Takes no body. A module that fails to export or write is reported in errors and does not fail the request, so a 200 does not mean every module was written - compare success_count with total_modules.
Generates a YAML seed snippet for the current permissions of one endpoint. IN PRACTICE THIS OPERATION CANNOT SUCCEED FOR ANY REGISTERED ENDPOINT, and the reason is the route pattern rather than the handler. {endpoint} is a single chi path segment, but every value it has to carry is a path of its own — /v1/customers and the like. Percent-encoding the slashes does not help: chi v5 routes on r.URL.RawPath whenever it is set, and neither the handler nor any middleware calls url.PathUnescape, so ExportEndpointToSeed receives the literal "%2Fv1%2Fcustomers", the endpoint = ? AND method = ? lookup misses, and the caller gets 404 rbac_m.endpoint_not_found. Sending the slashes undecoded adds path segments and does not match the route at all. Use POST /v1/rbac/endpoint-role/export, which takes the endpoint in a JSON body, until the route is fixed.